Description
|
|
Multiple vulnerabilities have been reported in Oracle Application Server, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
1) Input passed to idc/idcplg can be exploited to conduct SQL injection attacks.
For more information see vulnerability #1 in:
SA47610
2) Input appended to the URL after e.g. idc/help/user_help/wwhelp/wwhimpl/common/html/frameset.htm is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
3) Input passed to idc/idcplg can be exploited to conduct cross-site scripting attacks.
For more information see vulnerability #5 in:
SA47610
|